{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema \u0026 documentation and transparency \u0026 trust.",
    "b": {
      "slug": "whimsical",
      "name": "Whimsical MCP",
      "vendor": "Whimsical",
      "vendorUrl": "https://whimsical.com",
      "kind": "mcp",
      "category": "diagramming",
      "summary": "Official hosted MCP server for the Whimsical workspace.",
      "url": "https://www.anchorterminal.com/tools/whimsical",
      "markdownUrl": "https://www.anchorterminal.com/tools/whimsical.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/whimsical.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/whimsical.json",
      "repo": "https://github.com/WhimsicalCode/mcp-server-guide",
      "license": "proprietary",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.whimsical.com/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth 2.1 with PKCE, scopes profile, mcp:read and mcp:write. No API keys. The beta REST API also uses OAuth, with client secrets issued by support to approved workspaces.",
      "pricing": "freemium",
      "pricingNotes": "Free $0 with 50 board objects and 50 doc blocks a month, 10 AI credits a member and watermarked exports. Pro $10 an editor a month and Business $20 billed yearly, 17 per cent less than monthly billing. Pro removes the object limit. Every MCP tool works on Free, within those limits (https://whimsical.com/pricing).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 18,
      "popularity": {
        "githubStars": 5,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://whimsical.com/learn/integrations/mcp",
      "registryName": "com.whimsical/mcp",
      "capabilities": [
        "diagram.create",
        "diagram.edit",
        "diagram.export"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "mcp",
        "closed-source"
      ],
      "lastRelease": "2026-09-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 52.6,
        "grade": "D",
        "agentReady": false,
        "rank": 731,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 56,
          "payments": 25,
          "reliability": 60,
          "schema": 54,
          "security": 58,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.1 with PKCE and separate read and write scopes. No API keys, so it can't run headless or in CI.",
        "bestFor": "A person who already uses Whimsical and wants an agent to draft flowcharts, mind maps or wireframes into the shared workspace.",
        "strengths": [
          "OAuth 2.1 with PKCE and separate read and write scopes",
          "Flowcharts, mind maps, sequence diagrams, wireframes and docs, with automatic layout",
          "Status page with no incident since 6 March 2026",
          "SOC 2 Type II, a DPA and a published subprocessor list",
          "In the official MCP registry as com.whimsical/mcp, version 1.1.0 since 8 September 2026"
        ],
        "weaknesses": [
          "No API keys, so it can't run headless or in CI",
          "Rate limits and error responses aren't documented",
          "REST API is a closed, read-only beta",
          "Free plan caps creation at 50 board objects a month",
          "Export is PNG snapshots only. No SVG, draw.io or diagram code out"
        ],
        "agentNotes": [
          "Use `generate_diagram` or `generate_mind_map` for laid-out output rather than placing shapes with `create` and `edit`",
          "Call `how_to` for Whimsical's syntax before writing a large diagram",
          "Use `fetch` when you need a PNG snapshot of a board",
          "`delete` removes files or objects without asking. Confirm with the person first"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52.6
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 56,
          "payments": 25,
          "reliability": 60,
          "schema": 54,
          "security": 58,
          "transparency": 53
        },
        "provenanceScore": 87
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http whimsical https://mcp.whimsical.com/mcp",
        "config": {
          "mcpServers": {
            "whimsical": {
              "url": "https://mcp.whimsical.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/whimsical"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "per editor, billed yearly. Removes the Free object limit"
        },
        {
          "item": "Business plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "per editor, billed yearly. Adds SAML SSO and SCIM"
        }
      ],
      "provenance": {
        "legalEntity": "Whimsical, Inc.",
        "domain": "whimsical.com",
        "domainRegistered": "1998-09-26",
        "domainNote": "whimsical.com was registered in 1998, long before the product launched.",
        "endpointOnVendorDomain": true,
        "terms": "https://whimsical.com/terms",
        "privacy": "https://whimsical.com/terms/privacy",
        "statusPage": "https://status.whimsical.com",
        "changelog": "https://whimsical.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Address in the privacy policy is 1630 Welton Street, 7th Floor, Denver, Colorado 80202, USA",
          "The status page runs on Sorry and shows the last incident on 6 March 2026",
          "The MIT-licensed GitHub repo holds a setup guide and registry manifests, not the server",
          "security.txt not rechecked on 2026-10-01; none per the 30 September check"
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/whimsical.json",
      "live": {
        "slug": "whimsical",
        "probe": {
          "target": "https://mcp.whimsical.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T02:07:31.088165055Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 121,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 141,
          "p95ms24h": 327,
          "samples24h": 250,
          "samples30d": 2458,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.whimsical.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:25.376222116Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "com.whimsical/mcp",
            "version": "1.1.0",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          }
        ],
        "githubStars": 5,
        "securityTxt": {
          "url": "https://whimsical.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:11.656249626Z"
        },
        "domain": {
          "domain": "whimsical.com",
          "registered": "1998-09-26",
          "source": "https://rdap.verisign.com/com/v1/domain/whimsical.com",
          "checkedAt": "2026-10-04T13:09:41.71766445Z"
        },
        "pages": [
          {
            "url": "https://whimsical.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:27.654457305Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          },
          {
            "url": "https://whimsical.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:29.76289389Z",
            "changedAt": "2026-10-07T18:10:27.409239976Z",
            "fingerprint": "905ec975c078"
          },
          {
            "url": "https://whimsical.com/terms/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:33.887990047Z",
            "changedAt": "2026-10-07T18:10:31.508028193Z",
            "fingerprint": "ec70cf1f50af"
          },
          {
            "url": "https://whimsical.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:31.882860807Z",
            "changedAt": "2026-10-07T18:10:29.530100104Z",
            "fingerprint": "35cea982cfc7"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.whimsical.com/mcp",
          "checkedAt": "2026-10-09T21:40:56.148167863Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-09-30T21:57:09.851244047Z"
        },
        "updatedAt": "2026-10-10T02:07:31.088165055Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "Whimsical",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.whimsical.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "proprietary",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "18",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.whimsical/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-05",
        "b": "2026-09-08",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2025-07-30",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2025-08-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "5 stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema \u0026 documentation and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Kroki or Whimsical MCP?"
      },
      {
        "answer": "Kroki needs no key. Whimsical MCP uses an OAuth sign-in.",
        "question": "Do Kroki and Whimsical MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. Whimsical MCP has a hosted endpoint at https://mcp.whimsical.com/mcp.",
        "question": "Can an agent call Kroki and Whimsical MCP without installing anything?"
      },
      {
        "answer": "Kroki is open source (MIT). No open-source release is listed for Whimsical MCP.",
        "question": "Are Kroki and Whimsical MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 60",
          "Agent ergonomics, 70 against 46",
          "Payments \u0026 pricing, 60 against 25",
          "Maintenance \u0026 community, 86 against 56"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 54 against 48",
          "Transparency \u0026 trust, 70 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "A person who already uses Whimsical and wants an agent to draft flowcharts, mind maps or wireframes into the shared workspace.",
        "slug": "whimsical",
        "watchFor": "No API keys, so it can't run headless or in CI"
      }
    ],
    "job": {
      "capability": "diagram.create",
      "name": "Diagram creation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-whimsical.json",
        "title": "Cloudviz API vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-whimsical.json",
        "title": "D2 vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-whimsical.json",
        "title": "Diagrams.so API + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-whimsical.json",
        "title": "draw.io + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-whimsical.json",
        "title": "Eraser API + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-whimsical.json",
        "title": "Excalidraw vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-whimsical.json",
        "title": "Lucid API + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mermaid-chart-vs-whimsical.json",
        "title": "Mermaid Chart MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/mermaid-chart-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.json",
        "title": "Mural MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-whimsical.json",
        "title": "PlantUML vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/structurizr-vs-whimsical.json",
        "title": "Structurizr + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/structurizr-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/tldraw-vs-whimsical.json",
        "title": "tldraw SDK + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/tldraw-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 14,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "weight": 16,
        "whimsical": 60
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "whimsical",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "whimsical": 54
      },
      {
        "by": 24,
        "edge": "kroki",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "weight": 13,
        "whimsical": 46
      },
      {
        "by": 2,
        "edge": "whimsical",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "weight": 14,
        "whimsical": 58
      },
      {
        "by": 35,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "whimsical": 25
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 30,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "whimsical": 56
      },
      {
        "by": 8,
        "edge": "whimsical",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "whimsical": 70
      }
    ],
    "summary": "Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema \u0026 documentation and transparency \u0026 trust. Both do diagram creation.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "whimsical": "OAuth 2.1 with PKCE and separate read and write scopes. No API keys, so it can't run headless or in CI."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-whimsical",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.min.md"
  },
  "markdown": "Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema \u0026 documentation and transparency \u0026 trust. Both do diagram creation.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Whimsical MCP: grade D, 52.6/100, rank #731 of 950. Markdown https://www.anchorterminal.com/tools/whimsical.md · JSON https://www.anchorterminal.com/api/v1/tools/whimsical.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 60\n- Agent ergonomics, 70 against 46\n- Payments \u0026 pricing, 60 against 25\n- Maintenance \u0026 community, 86 against 56\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### Whimsical MCP (D)\n\nGood for: A person who already uses Whimsical and wants an agent to draft flowcharts, mind maps or wireframes into the shared workspace.\n\nAhead on:\n- Schema \u0026 documentation, 54 against 48\n- Transparency \u0026 trust, 70 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: No API keys, so it can't run headless or in CI\n\n\n## Score by category\n\n| Category | Weight | Kroki | Whimsical MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 60 | Kroki +14 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 54 | Whimsical MCP +6 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 46 | Kroki +24 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 58 | Whimsical MCP +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 25 | Kroki +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 56 | Kroki +30 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 70 | Whimsical MCP +8 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **59.2 · C** | **52.6 · D** | |\n\n## Facts side by side\n\n| Fact | Kroki | Whimsical MCP |\n| --- | --- | --- |\n| Kind | HTTP API | MCP server |\n| Vendor | Yuzu tech | Whimsical |\n| Hosted endpoint | no (local only) | `https://mcp.whimsical.com/mcp` |\n| Transports | HTTP | Streamable HTTP |\n| Auth | None | OAuth |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT | proprietary |\n| Tools exposed | none | 18 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| MCP registry | not listed | `com.whimsical/mcp` |\n| Last release | 2026-10-05 | 2026-09-08 |\n| Terms last updated | no document linked | 2025-07-30 |\n| Privacy policy last updated | no document linked | 2025-08-01 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 4.4k stars | 5 stars |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**Whimsical MCP.** OAuth 2.1 with PKCE and separate read and write scopes. No API keys, so it can't run headless or in CI.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### Whimsical MCP\n\n1. Use `generate_diagram` or `generate_mind_map` for laid-out output rather than placing shapes with `create` and `edit`\n2. Call `how_to` for Whimsical's syntax before writing a large diagram\n3. Use `fetch` when you need a PNG snapshot of a board\n4. `delete` removes files or objects without asking. Confirm with the person first\n\n## Questions\n\n### Which is better for AI agents, Kroki or Whimsical MCP?\n\nKroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema \u0026 documentation and transparency \u0026 trust.\n\n### Do Kroki and Whimsical MCP need an API key?\n\nKroki needs no key. Whimsical MCP uses an OAuth sign-in.\n\n### Can an agent call Kroki and Whimsical MCP without installing anything?\n\nNo hosted endpoint is listed for Kroki. Whimsical MCP has a hosted endpoint at https://mcp.whimsical.com/mcp.\n\n### Are Kroki and Whimsical MCP open source?\n\nKroki is open source (MIT). No open-source release is listed for Whimsical MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-whimsical.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-whimsical.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"whimsical\"}`. From a terminal: `anchor compare kroki whimsical`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/whimsical.json\n\n## Other comparisons with Kroki or Whimsical MCP\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs Whimsical MCP](https://www.anchorterminal.com/compare/cloudviz-vs-whimsical.md)\n- [D2 vs Whimsical MCP](https://www.anchorterminal.com/compare/d2-vs-whimsical.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-whimsical.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/drawio-vs-whimsical.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/eraser-vs-whimsical.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs Whimsical MCP](https://www.anchorterminal.com/compare/excalidraw-vs-whimsical.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Lucid API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/lucid-vs-whimsical.md)\n- [Mermaid Chart MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-whimsical.md)\n- [Mural MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.md)\n- [PlantUML vs Whimsical MCP](https://www.anchorterminal.com/compare/plantuml-vs-whimsical.md)\n- [Structurizr + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/structurizr-vs-whimsical.md)\n- [tldraw SDK + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/tldraw-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs Whimsical MCP",
        "url": ""
      }
    ],
    "description": "Kroki scores 59.2 (C) to Whimsical MCP's 52.6 (D) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "Whimsical MCP D 52.6",
      "scores"
    ],
    "h1": "Kroki vs Whimsical MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-whimsical.png",
    "path": "/compare/kroki-vs-whimsical",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs Whimsical MCP for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
